Skip to main content

How does Konfir keep my data secure?

Konfir uses security measures to protect your data, including encrypted connections, secure APIs, and platform-level safeguards.

Jacob avatar
Written by Jacob
Updated over 3 months ago

Summary

Konfir is built to the same standards used by banks and government services. Every connection and every part of our platform uses strong encryption and strict access controls, so your information stays secure at all times. Access is one-time, read-only, and handled via secure APIs — never by email or manual processes.


Data connection security

When you connect a source (Banking, HMRC, or Payroll), the connection is made using secure, encrypted APIs:

Banking (Open Banking)

You authenticate directly with your bank. Konfir receives only the salary/payment data needed for your verification. Login details never pass through or are seen by Konfir. Open Banking is regulated by the Financial Conduct Authority (FCA).

HMRC (Government Gateway)

You log in to your HMRC account and approve a one-time access request. Konfir receives a secure read-only snapshot of your PAYE or self-assessment data. Access closes automatically once data is retrieved.

Payroll

Data is transferred securely via APIs between your employer’s payroll provider and Konfir. Sensitive payroll data is never shared via email or manual files.

Why this matters: Unlike traditional referencing, no data is ever sent by email, spreadsheets, or PDFs between HR teams. Everything is handled through secure, encrypted channels with audit trails.


Data platform security

All information handled within Konfir is protected by multiple layers of security:

Encryption everywhere

All data is encrypted in transit (while moving) and at rest (while stored) using industry-standard protocols.

Strict access controls

Only authorised Konfir staff with a genuine operational need can access sensitive systems, managed through role-based permissions.

Audit & monitoring

We maintain continuous logging, intrusion detection, and regular penetration testing.

Infrastructure

Konfir runs entirely on Amazon Web Services (AWS), a leading provider of enterprise-grade cloud security and resilience.

Independent certification

Konfir is ISO 27001 certified and registered under the UK Digital Identity & Attributes Trust Framework (UKDIATF).


👉 In short: every connection you make is via secure, regulated APIs, and Konfir’s platform is designed and independently audited to bank-level security standards.


🤔 Still unsure?: If you have any questions or concerns about security, feel free to contact our support team at [email protected].

Did this answer your question?